I’m definitely for assuming that input is not safe by default. Especially with functions like poke/2 it will be common to interpolate in user or database strings. We can always wrap our own strings with ~E/.../ or whatever to send html instead of text.
1 Like






















